CVE-2024-13875: WP Programmmanager <= 1.2 - Reflected XSS
The WP-PManager WordPress plugin through 1.2 does not sanitise and escape a parameter before outputting it back in the page, leading to a Reflected Cross-Site Scripting which could be used against high privilege users such as admin.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2024-13875?
CVE-2024-13875 is considered to be a high severity vulnerability due to its potential exploitation against high privilege users.
How do I fix CVE-2024-13875?
To fix CVE-2024-13875, you should update the WP-PManager WordPress plugin to version 1.3 or later, which addresses the issue.
What type of vulnerability is CVE-2024-13875?
CVE-2024-13875 is a Reflected Cross-Site Scripting (XSS) vulnerability that affects the WP-PManager plugin.
Who is affected by CVE-2024-13875?
High privilege users, such as administrators, are particularly vulnerable to attacks exploiting CVE-2024-13875.
What does CVE-2024-13875 allow an attacker to do?
An attacker can leverage CVE-2024-13875 to execute arbitrary JavaScript in the context of an affected user's session.